Feed aggregator
There's a Heck of a Camera Inside This Colorfully Designed Phone
Supply Chain Compromises Impact Nx Console and GitHub Repositories
CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments—specifically CI/CD pipelines, code extensions and workflows.
Threat actors leveraged a prior compromise of Nx developer systems to compromise a GitHub employee’s device through a poisoned third-party VS Code extension, resulting in unauthorized access and exfiltration of internal GitHub repositories. The malicious extension version (18.95.0) was distributed through VS Code’s automatic update mechanism, meaning systems with Nx Console previously installed may have received the malicious build without developers taking any manual installation action. GitHub released a security advisory on this activity, and CVE-2026-48027 has been assigned to the malicious version of Nx Console and added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Additionally, in a campaign known as “Megalodon,” a cyber threat actor injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens, impacting both development and deployment pipelines in public GitHub repositories.
CISA urges organizations to implement the following recommendations to detect and remediate a potential compromise:
- Monitor and audit workflow files and contributor activity for suspicious pull requests and direct commits, particularly those authored by automated accounts.
- Revert unauthorized changes, especially from automated accounts, e.g., build-bot, auto-ci, ci-bot, pipeline-bot and especially those made after May 18, 2026.
If your organization discovers a compromise resulting from previously compromised GitHub or Nx Console software, CISA recommends the following steps:
- Conduct a forensics review of CI/CD logs, cloud audit trails, and affected developer machines.
- Rotate/revoke all secrets including: all credentials, tokens, and secrets accessible to CI/CD pipelines, including API keys, cloud provider credentials (Amazon Web Services, Google Cloud Platform, Microsoft Azure), SSH keys, Docker/npm/PyPI/Vault/Terraform/Kubernetes tokens, GitHub/GitLab/Bitbucket tokens, and developer or pipeline secrets.
- Notify proper stakeholders if necessary.
CISA recommends the following best practices for using package repos:
- Wait at least three hours before pulling a new package. This gives the software community time to identify suspicious or malicious packages before they are widely downloaded.
- Pin software to specific trusted versions. Pinning software prevents pulling a malicious or unscreened package during the build process.
- Only pull packages from known and trusted sources. Relying on known and trusted sources reduces the likelihood of downloading a package that has been maliciously forked.
See the following resources for additional guidance on these compromises:
- GitHub: Investigating unauthorized access to GitHub-owned repositories
- Nx: Postmortem: Nx Console v18.95.0 supply-chain compromise
- Ox Security: Megalodon: CI/CD Malware Spreading Across GitHub Repositories
- StepSecurity: Nx Console VS Code Extension Compromised
- SafeDep: Megalodon: Mass GitHub Repo Backdooring via CI Workflows
The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.
New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails
France-based startup Edamame says its runtime verification platform uses host telemetry and AI analysis to detect coding-agent “intent drift,” secret theft and supply-chain attacks in real time.
The post New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails appeared first on SecurityWeek.
Best Outdoor String Lights of 2026: Brighten Your Patio or Backyard With Our Top Picks
Oura Ring Is Rolling Out New Health-Tracking Features: When to Unlock Them
Computer Weekly speaks with Valerie Veatch, the director of a documentary charting the historical development of artificial intelligence, about the difficulties of challenging hype narratives and the pressing need to build a culture of technological...
The ramifications of Capita’s botched Civil Service pension contract continue as politicians distance themselves
Japanese Space Agency names arrival date for BepiColombo Mercury mission
Burn: Experimenting with FOCUS / CUR-based Kubernetes billing reconciliation
Article URL: https://github.com/tanrikuluozlem/burn
Comments URL: https://news.ycombinator.com/item?id=48307565
Points: 1
# Comments: 0
The first review of the pilot for AI prescriptions refills in Utah [pdf]
Article URL: https://commerce.utah.gov/wp-content/uploads/2026/05/Doctronic-Outcomes-May-2026.pdf
Comments URL: https://news.ycombinator.com/item?id=48307561
Points: 1
# Comments: 0
The Art of SIMD Programming (2022) [video]
Article URL: https://www.youtube.com/watch?v=vIRjSdTCIEU
Comments URL: https://news.ycombinator.com/item?id=48307549
Points: 1
# Comments: 0
Overview of Tornadoes in France (French)
Best Goodreads Alternatives in 2026
Article URL: https://www.pickupreader.com/blog/best-goodreads-alternatives-2026
Comments URL: https://news.ycombinator.com/item?id=48307517
Points: 1
# Comments: 0
QWOP
Article URL: https://en.wikipedia.org/wiki/QWOP
Comments URL: https://news.ycombinator.com/item?id=48307512
Points: 1
# Comments: 1
Reddit Launching Video Comments Feature
Article URL: https://old.reddit.com/r/modnews/comments/1tpa9p1/launching_video_in_comments/
Comments URL: https://news.ycombinator.com/item?id=48307502
Points: 1
# Comments: 0
The Dark Matter of Software
Article URL: https://99fires.substack.com/p/the-dark-matter-of-software
Comments URL: https://news.ycombinator.com/item?id=48307501
Points: 1
# Comments: 0
Look Ma No HTTP_proxy
Article URL: https://slicervm.com/blog/look-ma-no-proxy/
Comments URL: https://news.ycombinator.com/item?id=48307485
Points: 1
# Comments: 0
AnthropoSprawl: Timeline map of historical photos from pastvu.com
Article URL: https://anthroposprawl.eamag.me/
Comments URL: https://news.ycombinator.com/item?id=48307484
Points: 1
# Comments: 0
